Untrusted Search Path Vulnerability in OpenTelemetry.Resources.Host on macOS
CVE-2026-81192

7HIGH

Key Information:

Vendor
CVE Published:
8 September 2026

What is CVE-2026-81192?

The OpenTelemetry.Resources.Host NuGet package is impacted by an untrusted search path vulnerability specifically on macOS systems. Before version 1.16.0-beta.2, the host.id resource attribute detector executes the sh and ioreg commands without specifying an absolute path. This allows an attacker, with less privilege than the host application, to exploit the PATH environment variable and potentially execute arbitrary binaries in the context of the application. Such scenarios enable local code execution and escalate privileges. It is important to note that this vulnerability does not affect Linux or Windows hosts, and there are no known workarounds available for mitigation. A patch is included in version 1.16.0-beta.2.

Affected Version(s)

opentelemetry-dotnet-contrib < 1.16.0-beta.2

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.